logo

How a mistakenly published password exposed Mercedes-Benz source code

ID: 5c060a20-c8cc-5945-b5e3-9dd70cebccfa

STIX ID: report--5c060a20-c8cc-5945-b5e3-9dd70cebccfa

Feed Name: TechCrunch Security News

Threat Score
70/100

Date Published: 2024-01-26

Date Updated: 2026-04-23

Author: Carly Page

...
...

Mercedes-Benz inadvertently published an employee's GitHub authentication token in a public repository, which could have allowed unrestricted access to its internal GitHub Enterprise Server and hosted repositories. Security researchers found evidence the exposed repositories contained source code, Azure and AWS keys, a Postgres database and other sensitive internal information; Mercedes revoked the token and removed the public repo after disclosure, but the company has not confirmed whether any unauthorized access occurred.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.